• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 296
  • Last Modified:

Create a dmz on cisco851w

i need to creat a dmz on cisco851w EN PORT F0/0
NETWORK IP 176.16.10.0/24
DMZ-NAME-WEBSERVER
please need details steps and cisco commands?
* I will need to put a server on this port only.
Thanks,
0
Faustino-12
Asked:
Faustino-12
  • 2
  • 2
1 Solution
 
jmeggersCommented:
I would suggest you need zone-based firewall (ZBF) for this, assuming it's supported in software available for the 851W.  Without ZBF you can still create a separate VLAN for the server, but routing will treat it as any other interface.  The fact that you say "DMZ" implies to me that you want to restrict traffic in various ways. You can restrict traffic with access-lists, but the dynamic nature of traffic these days makes stateful firewalls much more appropriate.

The VLAN portion of what you need is pretty easy to do, but ZBF is not especially easy for an inexperienced user to configure.  You can take a look at http://www.cisco.com/en/US/partner/docs/ios/sec_data_plane/configuration/guide/sec_zone_polcy_firew.html for information.  At a basic level, you create policies (allow HTTP, block telnet, etc.) that get applied to zones, and link interfaces with those zones.  In your situation, you'd most likely have outside, inside and DMZ zones.  Without knowing specifics of your topology and policies, it's going to be very difficult for anyone on this site to tell you exactly what commands to configure.

If you don't have software that supports ZBF, my recommendation would be to front-end the router with an ASA 5505.
0
 
Faustino-12Author Commented:
ok so. i do not have zbf. what are the steps to configure my vlan on port f0/0
0
 
jmeggersCommented:
From the CLI:

enable
vlan database
vlan <new vlan #>

configure terminal
interface FA0/0
switchport mode access
switchport access vlan <new vlan #>
no shutdown

If you need to add a layer 3 interface with an IP address with a /24 subnet mask for the VLAN on the router:

configure terminal
interface vlan <new vlan #>
ip address a.b.c.d 255.255.255.0
0
 
Faustino-12Author Commented:
Thanks
0

Featured Post

Get quick recovery of individual SharePoint items

Free tool – Veeam Explorer for Microsoft SharePoint, enables fast, easy restores of SharePoint sites, documents, libraries and lists — all with no agents to manage and no additional licenses to buy.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now